Threat Intelligence

Warlock Ransomware Gang Targets Major Spanish and Portuguese Organisations

Dark Reading · 1 Oct 2026
Key Takeaway Australian SMBs should not assume geography protects them; maintain strong backups, patch systems promptly, and monitor for unusual network activity regardless of perceived risk level.

A threat group active for roughly a year is drawing attention from security researchers for behaving like both a cybercrime gang and a state-associated advanced persistent threat (APT). Known for deploying Warlock ransomware, the group has recently targeted large organisations in Spain and Portugal, regions not typically seen as frequent targets for this type of actor.

The group's dual nature, combining profit-driven ransomware tactics with the sophistication and patience often associated with nation-state actors, makes it harder for defenders to predict or categorise. Its willingness to strike in less common geographic markets suggests it is actively seeking out organisations that may have weaker defences or less experience dealing with advanced threat actors.

While details on the group's specific methods are still emerging, the pattern of hitting large, high-value organisations outside the usual target zones is a reminder that no region or industry should assume it is off the radar for sophisticated ransomware operators.

ransomware Warlock APT Spain Portugal

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.